• My Feed
  • Home
  • What's Important
  • Media & Entertainment
Search

Stay Curious. Stay Wanture.

© 2026 Wanture. All rights reserved.

  • Terms of Use
  • Privacy Policy
Tech/Software
Anthropic leak reveals Opus 4.7, Sonnet 4.8 in npm 2.1.88

31 March 2026

—

News

Rachel Stein

On March 30 and 31, 2025, Anthropic unintentionally exposed over 512,000 lines of TypeScript code from its Claude Code AI model through an npm source map file, a supply chain misstep that offers a rare window into the company's roadmap while underscoring a vulnerability that could ripple across any organization publishing JavaScript packages.

Why it matters: The exposure reveals previously undisclosed models (Opus 4.7, Sonnet 4.8, and a prototype named Capybara) alongside internal features such as a stealth "Cover Mode," a long term memory system called KAIROS, and even a virtual pet named BUDDY. More broadly, it highlights a systemic weakness in the software supply chain at a moment when credential leaks are accelerating at an unprecedented rate.

What they're saying: Anthropic has not issued a public statement. Industry analysts, however, note that the leak arrived during a broader surge in credential exposure across public code. GitGuardian's 5th edition State of Secrets Sprawl report, released on March 17, 2025, documented 28.65 million new hardcoded secrets in public GitHub commits during 2024 and an 81 percent year over year increase in AI service credential leaks.

Source map files translate minified JavaScript back to original source code, enabling debugging. When published publicly, they can be reverse engineered to reconstruct the original codebase.

Technical details of the exposure: The npm package version 2.1.88 included a .map file weighing 59.8 MB and covering roughly 1,900 files. Researchers extracted approximately 512,000 lines of TypeScript, revealing internal modules such as "Cover Mode" for stealth code contribution, the long term memory system KAIROS, a virtual pet named BUDDY, and a profanity based frustration tracker designed to gauge developer sentiment.

The pattern beneath the numbers: GitGuardian data shows commits co-authored by Claude Code exhibited a 3.2 percent secret leak rate, more than double the 1.5 percent baseline for all public commits. With public GitHub activity reaching 1.94 billion commits in 2024, a 43 percent year over year rise, the scale of the supply chain risk is no longer theoretical. It is structural.

Comparison with other major tech leaks: The 2024 Google Search documentation leak disclosed 350,000 lines of indexing code, while the Claude leak reveals 512,000 lines of active model logic and future model references, making the latter broader in scope and more directly tied to AI product roadmaps.

What's next: Experts warn that internal repositories are approximately six times more likely to contain hardcoded secrets, and 28 percent of leaks now originate from collaboration tools such as Slack, Jira, and Confluence. Moreover, 64 percent of valid secrets detected in 2022 remained active when re-tested in January 2025, indicating a persistent remediation gap that organizations have yet to close.

Recommended security measures for AI labs:

  1. Implement automated scanning of npm packages for accidental source map inclusion before publishing.
  2. Adopt secret management tools that rotate credentials on each commit.
  3. Enforce strict code review policies that flag hardcoded keys in both public and private repositories.
  4. Conduct regular penetration tests of the software supply chain, focusing on third party dependencies.
  5. Provide developer training on secure packaging practices and the risks of source map exposure.
  6. Integrate real time alerts for anomalous commit patterns using services like GitGuardian.
  7. Maintain an incident response playbook specific to supply chain breaches.

For a deeper look at Anthropic's model roadmap, see our earlier coverage of Claude Opus 4.5 for autonomous coding. The Claude Code leak underscores the urgent need for robust software supply chain security as AI development accelerates and the stakes of accidental exposure continue to rise.

banner

Feed

    Razer Unveils Pro Type Ergo Ergonomic Keyboard Today

    Razer Unveils Pro Type Ergo Ergonomic Keyboard Today

    Split design, AI button, and 19‑zone RGB aim at U.S. workers with a 9.7% RSI rate

    about 5 hours ago
    Google to debut screen‑free Fitbit band in 2026

    Google to debut screen‑free Fitbit band in 2026

    AI‑driven training plan and upgraded platform aim at the health‑tracking market against Oura and Whoop

    about 7 hours ago
    Nothing unveils AI‑powered smart glasses for a 2027 launch

    Nothing unveils AI‑powered smart glasses for a 2027 launch

    The glasses use a paired phone and cloud, with a clear frame and LED accents

    about 8 hours ago
    Google rolls out Veo 3.1 Lite, halving AI video costs

    Google rolls out Veo 3.1 Lite, halving AI video costs

    Veo 3.1 Lite matches Veo 3.1 Fast speed but cuts price by over 50% for devs now

    about 9 hours ago
    Freelander 97 Debuts 800‑V EV Crossover in Shanghai

    Freelander 97 Debuts 800‑V EV Crossover in Shanghai

    Chery‑JLR showcases ADS 4.1 autonomy on 800‑V platform, eyeing 2028 launch

    about 11 hours ago
    Telegram Launches Version 12.6 With AI Editor, New Polls

    Telegram Launches Version 12.6 With AI Editor, New Polls

    It adds an AI tone editor, richer polls, Live/Motion Photos, and bot management

    about 12 hours ago

    Pixel 11 Pro Renders Leak With Black Camera Bar and MediaTek Modem

    Google’s August 2026 flagship ditches Samsung radios for improved 5G and runs the Tensor G6

    1 day ago

    NVIDIA launches DLSS 4.5 with driver 595.97 on the RTX 50 series

    DLSS 4.5 scales to 6×, raising FPS from 85 to 210 on the RTX 5080 — ~3 ms latency

    1 day ago
    iOS 26.5 beta lands on iPhone 17 Pro with an 8 GB download

    iOS 26.5 beta lands on iPhone 17 Pro with an 8 GB download

    Apple restores RCS encryption and adds a 12‑month subscription in the update

    1 day ago
    Windows 11 24H2 Brings Dark Mode to Core Utilities

    Windows 11 24H2 Brings Dark Mode to Core Utilities

    Tools like Registry Editor get dark mode in Windows 11 24H2, out in Sep 2026

    2 days ago

    John Noble's 1,024 Thread Implant Powers Warcraft Raids

    John Noble, a former British parachutist turned veteran gamer, received a neural implant with 1,024 threads after a 2024 trial in Seattle. The device lets him control a MacBook with thought alone, turning World of Warcraft raids into hands‑free battles. His story shows how brain‑computer interfaces can expand digital access for disabled veterans and reshape gaming.

    3 days ago
    Apple unveils Siri app for iOS 27, adds 50+ AI agents

    Apple unveils Siri app for iOS 27, adds 50+ AI agents

    iOS 27 Siri app adds Extensions marketplace, eyeing Alexa’s 100,000‑skill store

    3 days ago
    OnePlus Nord CE6 Lite 5G Debuts with 7,000 mAh Battery

    OnePlus Nord CE6 Lite 5G Debuts with 7,000 mAh Battery

    A 6.7‑inch 120 Hz LCD and MediaTek Dimensity 6300 chip aim for two days of use

    3 days ago
    Microsoft PowerToys 0.98 adds Command Palette Dock

    Microsoft PowerToys 0.98 adds Command Palette Dock

    Pinnable panel brings shortcuts and system widgets to Windows 11

    3 days ago
    Sony stops CFexpress, SD card orders amid shortage

    Sony stops CFexpress, SD card orders amid shortage

    CFexpress Type A/B and SDXC/SDHC orders frozen as market seeks alternatives

    3 days ago
    China's PLA Debuts Distributed‑Control Ground Drone Pack

    China's PLA Debuts Distributed‑Control Ground Drone Pack

    Three variants (Shadow, Bloody, Polar) act as one organism without radio links

    3 days ago
    Xbox 360 Thrift Find Reveals 118GB GTA IV Dev Kit

    Xbox 360 Thrift Find Reveals 118GB GTA IV Dev Kit

    Five‑pound buy becomes a Rockstar North dev kit with 118GB GTA IV build

    3 days ago
    Apple removes nearly 100 VPN apps from Russia's App Store

    Apple removes nearly 100 VPN apps from Russia's App Store

    The July to September 2024 purge cuts VPNs that Russians use to bypass censorship

    5 days ago
    OpenAI’s March ad test pulls $8.3 million from U.S. users

    OpenAI’s March ad test pulls $8.3 million from U.S. users

    Test hit 20% of ChatGPT users, earning $0.11 per user, flagging a billion market

    5 days ago
    Loading...
banner
Tech/Software

Anthropic leak reveals Opus 4.7, Sonnet 4.8 in npm 2.1.88

31 March 2026

—

News

Rachel Stein

On March 30 and 31, 2025, Anthropic unintentionally exposed over 512,000 lines of TypeScript code from its Claude Code AI model through an npm source map file, a supply chain misstep that offers a rare window into the company's roadmap while underscoring a vulnerability that could ripple across any organization publishing JavaScript packages.

Why it matters: The exposure reveals previously undisclosed models (Opus 4.7, Sonnet 4.8, and a prototype named Capybara) alongside internal features such as a stealth "Cover Mode," a long term memory system called KAIROS, and even a virtual pet named BUDDY. More broadly, it highlights a systemic weakness in the software supply chain at a moment when credential leaks are accelerating at an unprecedented rate.

What they're saying: Anthropic has not issued a public statement. Industry analysts, however, note that the leak arrived during a broader surge in credential exposure across public code. GitGuardian's 5th edition State of Secrets Sprawl report, released on March 17, 2025, documented 28.65 million new hardcoded secrets in public GitHub commits during 2024 and an 81 percent year over year increase in AI service credential leaks.

Source map files translate minified JavaScript back to original source code, enabling debugging. When published publicly, they can be reverse engineered to reconstruct the original codebase.

Technical details of the exposure: The npm package version 2.1.88 included a .map file weighing 59.8 MB and covering roughly 1,900 files. Researchers extracted approximately 512,000 lines of TypeScript, revealing internal modules such as "Cover Mode" for stealth code contribution, the long term memory system KAIROS, a virtual pet named BUDDY, and a profanity based frustration tracker designed to gauge developer sentiment.

The pattern beneath the numbers: GitGuardian data shows commits co-authored by Claude Code exhibited a 3.2 percent secret leak rate, more than double the 1.5 percent baseline for all public commits. With public GitHub activity reaching 1.94 billion commits in 2024, a 43 percent year over year rise, the scale of the supply chain risk is no longer theoretical. It is structural.

Comparison with other major tech leaks: The 2024 Google Search documentation leak disclosed 350,000 lines of indexing code, while the Claude leak reveals 512,000 lines of active model logic and future model references, making the latter broader in scope and more directly tied to AI product roadmaps.

What's next: Experts warn that internal repositories are approximately six times more likely to contain hardcoded secrets, and 28 percent of leaks now originate from collaboration tools such as Slack, Jira, and Confluence. Moreover, 64 percent of valid secrets detected in 2022 remained active when re-tested in January 2025, indicating a persistent remediation gap that organizations have yet to close.

Recommended security measures for AI labs:

  1. Implement automated scanning of npm packages for accidental source map inclusion before publishing.
  2. Adopt secret management tools that rotate credentials on each commit.
  3. Enforce strict code review policies that flag hardcoded keys in both public and private repositories.
  4. Conduct regular penetration tests of the software supply chain, focusing on third party dependencies.
  5. Provide developer training on secure packaging practices and the risks of source map exposure.
  6. Integrate real time alerts for anomalous commit patterns using services like GitGuardian.
  7. Maintain an incident response playbook specific to supply chain breaches.

For a deeper look at Anthropic's model roadmap, see our earlier coverage of Claude Opus 4.5 for autonomous coding. The Claude Code leak underscores the urgent need for robust software supply chain security as AI development accelerates and the stakes of accidental exposure continue to rise.

Feed

    Razer Unveils Pro Type Ergo Ergonomic Keyboard Today

    Razer Unveils Pro Type Ergo Ergonomic Keyboard Today

    Split design, AI button, and 19‑zone RGB aim at U.S. workers with a 9.7% RSI rate

    about 5 hours ago
    Google to debut screen‑free Fitbit band in 2026

    Google to debut screen‑free Fitbit band in 2026

    AI‑driven training plan and upgraded platform aim at the health‑tracking market against Oura and Whoop

    about 7 hours ago
    Nothing unveils AI‑powered smart glasses for a 2027 launch

    Nothing unveils AI‑powered smart glasses for a 2027 launch

    The glasses use a paired phone and cloud, with a clear frame and LED accents

    about 8 hours ago
    Google rolls out Veo 3.1 Lite, halving AI video costs

    Google rolls out Veo 3.1 Lite, halving AI video costs

    Veo 3.1 Lite matches Veo 3.1 Fast speed but cuts price by over 50% for devs now

    about 9 hours ago
    Freelander 97 Debuts 800‑V EV Crossover in Shanghai

    Freelander 97 Debuts 800‑V EV Crossover in Shanghai

    Chery‑JLR showcases ADS 4.1 autonomy on 800‑V platform, eyeing 2028 launch

    about 11 hours ago
    Telegram Launches Version 12.6 With AI Editor, New Polls

    Telegram Launches Version 12.6 With AI Editor, New Polls

    It adds an AI tone editor, richer polls, Live/Motion Photos, and bot management

    about 12 hours ago

    Pixel 11 Pro Renders Leak With Black Camera Bar and MediaTek Modem

    Google’s August 2026 flagship ditches Samsung radios for improved 5G and runs the Tensor G6

    1 day ago

    NVIDIA launches DLSS 4.5 with driver 595.97 on the RTX 50 series

    DLSS 4.5 scales to 6×, raising FPS from 85 to 210 on the RTX 5080 — ~3 ms latency

    1 day ago
    iOS 26.5 beta lands on iPhone 17 Pro with an 8 GB download

    iOS 26.5 beta lands on iPhone 17 Pro with an 8 GB download

    Apple restores RCS encryption and adds a 12‑month subscription in the update

    1 day ago
    Windows 11 24H2 Brings Dark Mode to Core Utilities

    Windows 11 24H2 Brings Dark Mode to Core Utilities

    Tools like Registry Editor get dark mode in Windows 11 24H2, out in Sep 2026

    2 days ago

    John Noble's 1,024 Thread Implant Powers Warcraft Raids

    John Noble, a former British parachutist turned veteran gamer, received a neural implant with 1,024 threads after a 2024 trial in Seattle. The device lets him control a MacBook with thought alone, turning World of Warcraft raids into hands‑free battles. His story shows how brain‑computer interfaces can expand digital access for disabled veterans and reshape gaming.

    3 days ago
    Apple unveils Siri app for iOS 27, adds 50+ AI agents

    Apple unveils Siri app for iOS 27, adds 50+ AI agents

    iOS 27 Siri app adds Extensions marketplace, eyeing Alexa’s 100,000‑skill store

    3 days ago
    OnePlus Nord CE6 Lite 5G Debuts with 7,000 mAh Battery

    OnePlus Nord CE6 Lite 5G Debuts with 7,000 mAh Battery

    A 6.7‑inch 120 Hz LCD and MediaTek Dimensity 6300 chip aim for two days of use

    3 days ago
    Microsoft PowerToys 0.98 adds Command Palette Dock

    Microsoft PowerToys 0.98 adds Command Palette Dock

    Pinnable panel brings shortcuts and system widgets to Windows 11

    3 days ago
    Sony stops CFexpress, SD card orders amid shortage

    Sony stops CFexpress, SD card orders amid shortage

    CFexpress Type A/B and SDXC/SDHC orders frozen as market seeks alternatives

    3 days ago
    China's PLA Debuts Distributed‑Control Ground Drone Pack

    China's PLA Debuts Distributed‑Control Ground Drone Pack

    Three variants (Shadow, Bloody, Polar) act as one organism without radio links

    3 days ago
    Xbox 360 Thrift Find Reveals 118GB GTA IV Dev Kit

    Xbox 360 Thrift Find Reveals 118GB GTA IV Dev Kit

    Five‑pound buy becomes a Rockstar North dev kit with 118GB GTA IV build

    3 days ago
    Apple removes nearly 100 VPN apps from Russia's App Store

    Apple removes nearly 100 VPN apps from Russia's App Store

    The July to September 2024 purge cuts VPNs that Russians use to bypass censorship

    5 days ago
    OpenAI’s March ad test pulls $8.3 million from U.S. users

    OpenAI’s March ad test pulls $8.3 million from U.S. users

    Test hit 20% of ChatGPT users, earning $0.11 per user, flagging a billion market

    5 days ago
    Loading...